{"id":15391,"plugin_id":"plugin_connector_1p_c5b7d5df5d7081918f2c4be5a633ed5d","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:11:22.106Z","digest":"883100b7387395785fe8b9b3223db8d2c6737edcc14a37aad693e48112ed85b5","against":null,"payload":{"name":"cloud-environment-runtime","description":"Read at the start of work in a managed cloud environment. Inspect network policy and configured credentials; build and run Docker containers with the session proxy and CA trust; use Tailscale VPN access, configure TCP forwarding, and diagnose access failures.","included_files":[{"relative_path":"references/docker.md","size_in_bytes":6363},{"relative_path":"references/networking.md","size_in_bytes":1688},{"relative_path":"references/vpn.md","size_in_bytes":8927},{"relative_path":"scripts/ensure-socat.sh","size_in_bytes":2962}],"skill_md_contents":"---\nname: cloud-environment-runtime\ndescription: Read at the start of work in a managed cloud environment. Inspect network policy and configured credentials; build and run Docker containers with the session proxy and CA trust; use Tailscale VPN access, configure TCP forwarding, and diagnose access failures.\n---\n\nRead this skill at the start of work in a managed cloud environment, including\nresumed work. Before building or running Docker containers, read\n[Docker in Docker](references/docker.md) and follow its proxy and CA guidance.\n\nUse `cloud_environment.environment_status` at the start of work in a managed cloud\nenvironment and when diagnosing network or authentication failures. It takes no\narguments. The runtime selects the instance and checks access as the task's actor.\nThe result describes the thread's managed instance; it does not describe extra\nattached environments or the latest editable configuration draft.\n\nBefore network work, read [Cloud environment networking](references/networking.md)\nand inspect the selected executor's `/etc/codex/network-policy.json`. If the\nsupported policy snapshot reports `vpn_configured: true`, also read\n[Tailscale VPN access](references/vpn.md). The flag indicates configuration,\nnot VPN health. Also read the VPN reference when explicitly diagnosing VPN access,\neven if the flag is missing or false. `environment_status` reports HTTP policy\nand credential readiness, not TCP grants or VPN health.\n\nUse the returned network policy, secret bindings, runtime variable names, and\noutbound identity aliases to plan commands. Do not print credential values, dump\nthe process environment, or inspect secret files to discover their contents.\nA configured variable may hold a proxy placeholder; that alone does not mean its\ncredential is missing. Use the configured SDK or CLI normally.\n\nTreat desired configuration and observed readiness separately. Require\n`observations_current: true` and the individual state `ready` before treating a\nsecret, runtime variable, or outbound identity as ready. Network policy is applied\nonly when its current state is `enforced`. Missing or any other states, including\n`skipped` and `unsupported`, do not establish readiness. Recheck after setup\ncompletes. Ready observations describe setup, not guaranteed authorization for\nevery remote API call. Diagnose the actual command's error too.\n\nFor CLI or SDK profile selection, read the worker's non-secret JSON manifest at\n`OIC_MANIFEST_PATH`, if present. Version 1 contains a `connections` list. Select\nthe entry whose `alias` matches the identity needed for the task; `is_default`\nidentifies the provider's default, not necessarily the intended identity. Use the\nselected entry's fields to set these environment variables for that command only:\n\n| `provider_kind` | Environment variable ← manifest field |\n| --- | --- |\n| `azure` | `IDENTITY_ENDPOINT` ← `identity_endpoint`; `AZURE_CONFIG_DIR` ← `config_dir` |\n| `aws` | `AWS_PROFILE` ← `alias`; `AWS_CONFIG_FILE` ← `config_file` |\n| `gcp` | `CLOUDSDK_CONFIG` ← `config_dir`; `CLOUDSDK_ACTIVE_CONFIG_NAME` ← `configuration_name`; `GOOGLE_APPLICATION_CREDENTIALS` ← `credentials_file` |\n\nPreserve the inherited runtime authentication headers and guard variables. Use\ncredential file paths as selectors without reading or printing their contents.\nDo not invent aliases, replace injected credentials, or start interactive login\nmerely because a token is not visible. Inspect the entry's `setup` outcome when\ndiagnosing CLI failures; a warning does not establish successful CLI setup. If\nthe manifest version, required entry, or selector fields are unavailable or\nunsupported, report the missing setup instead of silently using another identity.\n\nThis plugin reads runtime context. Configuration changes require the environment\nconfiguration workflow and its user review. If the tool reports no attached\nmanaged environment, do not reuse an instance ID or readiness result from a prior\nturn.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}